CVE-2024-53375

An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.
Configurations

No configuration.

History

17 Dec 2024, 21:15

Type Values Removed Values Added
Summary (en) Authenticated remote code execution (RCE) vulnerabilities affect TP-Link Archer, Deco, and Tapo series routers. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the installation or activation of the HomeShield functionality. (en) An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.

03 Dec 2024, 20:15

Type Values Removed Values Added
Summary
  • (es) Las vulnerabilidades de ejecución remota de código (RCE) autenticada afectan a los enrutadores de las series Archer, Deco y Tapo de TP-Link. Existe una vulnerabilidad en la función "tmp_get_sites" de la funcionalidad HomeShield proporcionada por TP-Link. Esta vulnerabilidad aún se puede explotar sin la instalación o activación de la funcionalidad HomeShield.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-78

02 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-02 22:15

Updated : 2024-12-17 21:15


NVD link : CVE-2024-53375

Mitre link : CVE-2024-53375

CVE.ORG link : CVE-2024-53375


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')